Privacy Policy
Last updated: February 23, 2026
Thank you for using Uniq Winders. This privacy policy informs you about how the Uniq Winders mobile application and associated physical product (connected watch winder) handle your data.
Uniq Winders is published by a Swiss company and complies with the Swiss Federal Act on Data Protection (nFADP), the General Data Protection Regulation (GDPR) for European Union and European Economic Area users, and applicable U.S. privacy laws including the California Consumer Privacy Act (CCPA/CPRA).
1. Data Controller
Uniq Winders
Switzerland
Contact: hello@uniq-luxury.com
For any questions regarding the protection of your data, you may contact us at the address above.
2. Collection and Use of Information
- No user account required: Using the application does not require creating an account or providing personal information such as your name, email address, or phone number.
- Technical device identifier: Each watch winder has a unique identifier generated by cryptographic hashing (SHA-256) of the electronic component's MAC address, combined with a random salt. This identifier cannot be reversed to the original MAC address due to the one-way nature of the hash. It is used exclusively for technical communications (parameter synchronization, firmware updates). This identifier is not considered personal data as it is not linked to any identifiable person and does not allow any profiling or user tracking.
-
IoT Features (voluntary activation):
- The application communicates with our cloud infrastructure hosted in Switzerland to provide certain IoT features (remote control, parameter synchronization).
- These services are only activated if the user explicitly chooses to enable them in the application after reading and accepting the IoT consent dialog.
- Data transmitted is exclusively technical: winder identifier, battery level (in millivolts), rotation parameters (number of turns, interval, direction, speed), and firmware version.
- No personal, behavioral, or personally identifiable data is collected or transmitted.
- Wi-Fi connection: If you choose to connect your winder to your Wi-Fi network, the network name (SSID) is stored locally on the device. The Wi-Fi password is handled internally by the device's wireless module for automatic reconnection and is protected by hardware flash encryption (AES-256). The Wi-Fi password is never transmitted to our servers.
- No tracking: The application does not include any analytics SDK, advertising tracker, or behavioral profiling tool. No advertising identifier is collected.
- Minimal permissions: The application only requests Bluetooth permission, necessary for communicating with your winder. No location, camera, microphone, or storage permissions are required.
3. Device Security Architecture
Your Uniq Winders watch winder incorporates a professional-grade multi-layered security architecture:
- Bluetooth (BLE) communication: All Bluetooth communications use the Secure Connections protocol with pairing and bonding. Sensitive characteristics (parameters, Wi-Fi credentials, OTA updates) are protected by link-layer encryption and are only accessible to paired devices. Pairing requires pressing a physical button on the device, preventing any remote bonding attempt.
- Data encryption at rest: The device firmware is protected by hardware flash encryption (AES-256). Secrets stored in non-volatile memory are also encrypted. No sensitive data is readable even with physical access to the electronic component.
- Secure Boot: Each device startup verifies firmware authenticity through a cryptographic signature. Only firmware signed by Uniq Winders can run on the device.
- Unique per-device secrets: Each winder possesses a unique 256-bit cryptographic secret generated during manufacturing. This secret is used for server authentication and update encryption. Compromising one device does not compromise any other.
- Anti-rollback protection: A hardware counter prevents installation of an earlier firmware version, protecting against downgrade attacks.
4. Firmware Updates (OTA)
Firmware updates benefit from a four-layer protection system:
- Encrypted BLE transport: Update data travels via Bluetooth Low Energy between your phone and the winder over an encrypted connection after pairing.
- Unique key encryption (AES-256): The firmware is encrypted server-side using the AES-256 algorithm with a key derived from your device's unique secret. Only your device can decrypt the update intended for it.
- Signature verification: After decryption, the device's secure bootloader verifies the cryptographic signature of the firmware. Any malicious modification is detected and the firmware rejected.
- Anti-rollback protection: The hardware counter prevents any downgrade to a previous firmware version.
- Consent: Functional updates are offered to the user who can choose whether to install them. Critical security updates may be strongly recommended.
- Resilience: In case of issues during an update, a protection mechanism preserves device functionality.
5. Software Support Duration
- Maintenance commitment: In accordance with the European Cyber Resilience Act (CRA), we commit to providing security updates for your product for a minimum period of 5 years from the date of purchase, or until December 31, 2031 at minimum.
- Functional updates: Functional improvements may be offered beyond this period, without obligation on our part.
- Offline operation: Your winder remains fully functional even without Internet connection or updates, using locally stored settings.
6. Data Sharing and Technical Infrastructure
- Swiss infrastructure: The application communicates exclusively with our backend server located in Switzerland. All requests from your device pass through this Swiss infrastructure.
- Technical subcontractors: Our Swiss server uses Google Firebase (hosted in the United States) for application authentication (App Check) and technical real-time synchronization. Data transferred is exclusively technical (hardware identifier, configuration parameters, battery level, firmware version).
- Application protection: The mobile application is protected by Firebase App Check using Play Integrity (Android) and App Attest (iOS), preventing unauthorized access to our infrastructure.
- Nature of data: The information transmitted does not constitute personal data under GDPR/nFADP as it does not allow identification of a natural person. It is solely technical information related to device operation.
- No advertising or commercial use: Uniq Winders does not use any data for marketing, advertising, or analytics purposes. Google Firebase is configured in strictly technical mode without sharing with other Google services.
- No data sales: We do not sell, rent, or trade any data with third parties.
7. International Transfers
- Primary location: Our backend server is hosted in Switzerland.
- Third-party services: Our Swiss server communicates with Firebase (Google LLC, United States) for application authentication and data synchronization.
- Risk minimization: In accordance with the principle of data minimization, only non-personal technical information is transmitted. The absence of personal data in these flows makes this transfer GDPR-compliant.
- Contractual safeguards: Our contracts with Google include Standard Contractual Clauses (SCCs) approved by the European Commission to govern data transfers.
8. Tracking Technologies and Cookies
- No cookies or tracking: The application does not use cookies, tracking technologies, profiling tools, or advertising identifiers.
9. Security Measures
- Communication encryption: All communications with our servers are encrypted via TLS 1.2/1.3 (HTTPS) with certificate pinning to verify our server's identity.
- Per-device authentication: Each request to our servers is authenticated by a cryptographic signature using the device's unique secret, with replay attack protection.
- Hardware security: Secure Boot, flash encryption (AES-256), and anti-rollback protection via hardware counter. Debug interfaces are permanently disabled.
- Rate limiting: Our servers enforce request rate limiting per device and per IP address to prevent abuse.
- Data minimization: Only data strictly necessary for operation is collected and transmitted.
10. Your Rights (GDPR / nFADP)
- Right of access: You can ask us what data is associated with your device identifier.
- Right to rectification: You can request correction of inaccurate data associated with your device.
- Right to deletion: You can request deletion of data associated with your device by contacting us.
- Right to restriction: You can request restriction of processing of your data in cases provided by law.
- Right to object: You can disable IoT features at any time from the application, which stops all communication with our servers.
- Right to portability: Upon request, we can provide you with the technical data associated with your device in a readable, structured format.
- Complaint: You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or the competent supervisory authority in your EU/EEA country of residence.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- No sale of personal information: We do not sell any personal information and have never done so.
- No sharing for advertising: We do not share any personal information for cross-context behavioral advertising purposes.
- No financial incentives: We do not offer financial incentives in exchange for personal information.
- Right to know: You may request the categories and specific pieces of personal information we have collected about you.
- Right to delete: You may request the deletion of personal information we have collected.
- Non-discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
12. Children's Privacy
- The Uniq Winders application and product are not intended for children under 16 years of age.
- We do not knowingly collect data from children. If you are a parent or guardian and believe your child has provided us with information, please contact us at hello@uniq-luxury.com so we can take appropriate action.
13. Data Retention
- Technical data associated with your device is retained as long as the device is active and connected to our IoT services.
- Data is deleted upon simple request to hello@uniq-luxury.com.
- Disabling IoT features in the application immediately stops data transmission to our servers.
14. Consent and Modifications
- Voluntary activation of IoT features: Use of IoT features is subject to your explicit consent via the application's consent dialog and constitutes acceptance of technical communication with our servers.
- Optional updates: Firmware updates are offered but not imposed, except for critical security patches which may be strongly recommended.
- User control: The user can disable IoT features at any time from the application settings.
- Policy modifications: Any material changes to this policy will be communicated via an application update or via its page on application stores. The last update date will be modified accordingly.
15. Product Liability
- Legal warranty: The physical product is covered by the legal conformity warranty applicable in your country of residence.
- Updates and warranty: A software update performed via our official application does not void the product warranty.
- Unauthorized modifications: Any modification of the firmware by unofficial means may result in loss of warranty and irreversible damage to the device.
16. Contact
For any questions regarding this privacy policy, to exercise your rights, or to report a security issue, please contact us:
hello@uniq-luxury.com
Data controller: Uniq Winders, Switzerland.
Terms of Service
Last updated: February 23, 2026
These Terms of Service (ToS) govern the use of the Uniq Winders mobile application and the associated physical product (connected watch winder).
1. Acceptance of Terms
- Use of the application: By downloading and using the Uniq Winders application, you agree to be bound by these ToS.
- Modifications: We reserve the right to modify these ToS at any time. Changes will be communicated via the application or app stores.
- Use of the physical product: Use of the watch winder is subject to these ToS as well as the legal warranty applicable in your country of residence.
2. Application License
- Limited license: We grant you a personal, non-exclusive, non-transferable, and revocable license to use the application for personal, non-commercial purposes.
- Restrictions: You agree not to decompile, disassemble, reverse engineer, or attempt to extract the source code of the application.
- Intellectual property: All rights, title, and interest in the application and firmware remain our exclusive property.
3. Use of Physical Product
- Proper use: The watch winder must be used in accordance with the user manual instructions.
- Liability limits: We are not responsible for damage to watches caused by improper use of the product (inappropriate settings, incompatible watches, etc.).
- Maintenance: The user is responsible for regular cleaning and maintenance of the product according to provided recommendations.
4. Firmware Updates (OTA)
- Consent required: Functional firmware updates require your explicit consent via the application.
- Security updates: Critical security updates may be strongly recommended. Refusing to install these updates may expose your device to vulnerabilities.
- Update process: During the update, do not unplug the device and keep your phone nearby. An interruption may require technical intervention.
- Update security: Updates are encrypted (AES-256) with a key unique to your device and cryptographically signed. Your device verifies authenticity before installation.
- Unofficial firmware: Installing firmware from unofficial sources immediately voids the warranty and may irreversibly damage your device.
5. IoT Features and Connectivity
- Optional activation: IoT features (remote control, cloud synchronization) are optional and require an Internet connection as well as your explicit consent.
- Service availability: We strive to maintain cloud services available at all times but do not guarantee uninterrupted availability.
- Offline operation: The product remains fully functional without Internet connection using local settings.
6. Warranty and Liability
- Legal warranty: The physical product benefits from the legal conformity warranty applicable in your country of residence (typically 2 years in Europe, applicable implied warranties in the United States).
- Warranty exclusions: The warranty does not cover:
- Damage caused by improper use or accident
- Normal wear and tear of the product
- Unauthorized modifications to firmware or hardware
- Damage to watches caused by inappropriate settings
- Limitation of liability: To the extent permitted by law, our liability is limited to the purchase price of the product.
7. Technical Support
- Support duration: We commit to providing technical support and security updates for at least 5 years from the date of purchase, or until December 31, 2031 at minimum.
- Contact: For any assistance: hello@uniq-luxury.com.
- Documentation: User manuals and troubleshooting guides are available in the application.
8. Security and Privacy
- Privacy Policy: Your use of the application is also governed by our Privacy Policy.
- Your environment security: You are responsible for the security of your mobile device and your Wi-Fi network configuration.
- Vulnerability reporting: If you discover a security flaw, please inform us immediately at hello@uniq-luxury.com. We commit to handling all reports with diligence.
9. Termination
- User termination: You may stop using the application at any time by uninstalling it.
- Termination by us: We may suspend or terminate your access to cloud services in case of violation of these ToS.
- Effect of termination: The physical product will continue to operate locally even after termination of access to cloud services.
10. Applicable Law and Jurisdiction
- Swiss law: These ToS are governed by Swiss law.
- Jurisdiction: Any dispute will be submitted to the exclusive jurisdiction of Swiss courts, subject to mandatory consumer protection provisions of your country of residence.
- Consumer rights: Consumers in the EU/EEA and the United States benefit from mandatory protections granted by the legislation of their country of residence.
11. Contact
For any questions regarding these Terms of Service:
hello@uniq-luxury.com
Uniq Winders, Switzerland.